Cedars-Sinai Health System
Disclosed Aug 22, 201412 years ago33,136 affectedConfirmed
The covered entity (CE), Cedars-Sinai Health System, reported that an employee’s unencrypted laptop computer was stolen during a residential burglary. Although the computer was used primarily for troubleshooting pathology software, some electronic protected health information (ePHI) of approximately 33,136 individuals was potentially stored in temporary files on the laptop’s hard drive. The CE terminated the laptop’s remote access capabilities and conducted an internal investigation. Although the CE’s laptops are encrypted as per its policy, the encryption for this laptop was disabled by a helpdesk service provider when providing assistance. The CE provided breach notification to HHS, affected individuals, and the media, and posted notice of the incident on its website. The CE has not learned of any identity theft or other misuse of the potentially affected information resulting from this incident. Following OCR’s investigation, the CE updated its policies and procedures related to the storage, transmission and encryption of ePHI, as well as the enforcement of its employees’ adherence to these policies and procedures.
What is known
| People affected | 33,136 (as reported to HHS) |
|---|---|
| Disclosed | Aug 22, 2014 |
| Happened | Jun 23, 2014 |
| Attack | Lost or stolen device |
| Data exposed | Names, Health |
| Sector | Healthcare · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| California Attorney General breach notice: Cedars-Sinai Health Systemoag.ca.gov · Official notice | Official notice |
| HHS OCR breach report (archive, resolved): Cedars-Sinai Health System (Healthcare Provider, CA)ocrportal.hhs.gov · Official notice | Official notice |
Notices filed
| Where | Filed | People |
|---|---|---|
| California AGresidents of CA | Aug 22, 2014 | |
| California AGresidents of CA | Sep 10, 2014 | |
| HHS archivetotal | Sep 10, 2014 | 33,136 |
History of this record
- 2026-09-25 · attack: unknown to lost-device · backfill source
- 2026-09-25 · data_types: [] to ["names","health"] · backfill source
- 2026-09-25 · records_basis: empty to hhs · backfill source
- 2026-09-25 · records: empty to 33136 · backfill source
- 2026-09-25 · summary: empty to The covered entity (CE), Cedars-Sinai Health System, reported that an employee’s unencrypted laptop computer was stolen during a residential burglary. Although the computer was used primarily for troubleshooting pathology software, some ele · backfill source
- 2026-09-25 · disclosed: 2014-09-10 to 2014-08-22 · backfill source
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.